Critical Vulnerabilities in GitHub Copilot, Gemini CLI, Claude, and Other Tools Impact Millions of Users
ID: 7095f346-ca6d-55a1-a0ee-753b56ffddcd
STIX ID: report--7095f346-ca6d-55a1-a0ee-753b56ffddcd
Feed Name: cybersecurityNews.com
The report details "IDEsaster," a vulnerability class where AI coding assistants integrated into IDEs can be coerced to overwrite global IDE configuration and workspace files, enabling remote code execution and data exfiltration; the research found over 30 issues with 24 CVEs assigned across major products (e.g., GitHub Copilot, Cursor, JetBrains Junie), and demonstrates attack chains that leverage IDE features like .vscode/settings.json and .idea/workspace.xml to execute malicious payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
